CVE-2021-24014: Cross-site scripting in FSA due to unsafe use of templating functions
Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthenticated attacker to perform an XSS attack via specifically crafted request parameters.
Other sources
Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox may allow an unauthenticated attacker to perform an XSS attack via specifically crafted request parameters.
— FortiGuard
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24014?
CVE-2021-24014 is a vulnerability in FortiSandbox before version 4.0.0 that allows an unauthenticated attacker to perform an XSS attack through specially crafted request parameters.
What is the severity of CVE-2021-24014?
The severity of CVE-2021-24014 is medium with a CVSS score of 6.1.
How does CVE-2021-24014 affect FortiSandbox?
CVE-2021-24014 affects FortiSandbox versions before 4.0.0, allowing an unauthenticated attacker to perform an XSS attack.
What is the Common Weakness Enumeration (CWE) of CVE-2021-24014?
The CWE of CVE-2021-24014 is CWE-79, which represents improper neutralization of input during web page generation.
How can I fix CVE-2021-24014 in FortiSandbox?
To fix CVE-2021-24014, it is recommended to upgrade FortiSandbox to version 4.0.0 or later.